Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

rukovoditel 3.2.1 Cross Site Scripting

rukovoditel version 3.2.1 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#web#mac#windows#apple#google#git#php#auth#chrome#webkit
Moodle LMS 4.0 Cross Site Scripting

Moodle LMS version 4.0 suffers from a cross site scripting vulnerability.

Tunnel Interface Driver Denial Of Service

Tunnel Interface Driver suffers from a denial of service vulnerability.

OPSWAT Metadefender Core 4.21.1 Privilege Escalation

OPSWAT Metadefender Core version 4.21.1 suffers from a privilege escalation vulnerability.

X-Skipper-Proxy 0.13.237 Server-Side Request Forgery

X-Skipper-Proxy version 0.13.237 suffers from a server-side request forgery vulnerability.

Subrion CMS 4.2.1 Cross Site Scripting

Subrion CMS version 4.2.1 suffers from a persistent cross site scripting vulnerability.

CVE-2023-25260: LFI in Stimulsoft Designer - CVE-2023-25260

Stimulsoft Designer (Web) 2023.1.3 is vulnerable to Local File Inclusion.

CVE-2023-27701: MuYucms sqldel.html has Arbitrary file deletion vulnerability · Issue #9 · MuYuCMS/MuYuCMS

MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.

CVE-2022-47529

Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.